Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. This is fixed in MMR v1.3.8. Users are advised to upgrade. Restricting which hosts MMR is allowed to contact via (local) firewall rules or a transparent proxy and may provide a workaround for users unable to upgrade.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 16 Jan 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. This is fixed in MMR v1.3.8. Users are advised to upgrade. Restricting which hosts MMR is allowed to contact via (local) firewall rules or a transparent proxy and may provide a workaround for users unable to upgrade. | |
Title | Server-Side Request Forgery (SSRF) on redirects and federation in Matrix Media Repo | |
Weaknesses | CWE-918 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-16T19:14:46.822Z
Updated: 2025-02-12T20:31:21.571Z
Reserved: 2024-11-14T15:05:46.771Z
Link: CVE-2024-52602

Updated: 2025-02-12T20:26:20.362Z

Status : Received
Published: 2025-01-16T20:15:32.503
Modified: 2025-01-16T20:15:32.503
Link: CVE-2024-52602

No data.